T09 · Insecure Skill Coding Practices
- Location
scripts/run.py:24- Finding
Unvalidated API Base URL Can Expose Credentials and User Content
- Content
View full analysis
Vulnerability Details
File Location:
scripts/run.py:24-39, 76-83
Vulnerability Type: Arbitrary outbound endpoint and credential disclosure
Risk Level: MediumVulnerable Code
python def build_base_url(): return os.getenv("AISKILLS_BASE_URL", DEFAULT_BASE_URL).rstrip("/") def build_headers(): api_key = os.getenv("AISKILLS_API_KEY", "").strip() tenant_id = os.getenv("AISKILLS_TENANT_ID", "default").strip() or "default" if not api_key: fail("AISKILLS_API_KEY is required") return { "Content-Type": "application/json", # Cloudflare blocks urllib's default Python user agent for this endpoint. "User-Agent": "ai-skills-runner/1.0 (+https://ai-skills.ai)", "Accept": "application/json", "X-API-Key": api_key, "X-Tenant-Id": tenant_id, }python def request_json(method, path, payload): body = json.dumps(payload).encode("utf-8") req = urllib.request.Request( f"{build_base_url()}{path}", data=body, method=method, headers=build_headers(), ) try: with urllib.request.urlopen(req, context=SSL_CONTEXT) as response: return json.loads(response.read().decode("utf-8"))Technical Analysis
The request origin is taken directly from the
AISKILLS_BASE_URLenvironment variable without validation of its scheme, hostname, port, or trust relationship. Every request to the resulting URL includes theAISKILLS_API_KEYandAISKILLS_TENANT_IDauthentication headers. The request body also includes user-provided copywriting inputs.Consequently, a party capable of controlling the runner's environment can redirect requests to an arbitrary server. The implementation does not require HTTPS, enforce an approved hostname, or conditionally attach credentials only to the expected API origin. HTTPS certificate verification protects connections to the hostname selected by the environment variable, but it does not e ...[truncated 1777 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the execution endpoint to
https://ai-skills.aiwhen endpoint customization is not operationally required. - If customization is required, parse the configured URL and enforce:
- The
httpsscheme. - An explicit allowlist of trusted hostnames.
- Approved ports only.
- No embedded user information.
- No query string or fragment.
- The
- Attach
X-API-KeyandX-Tenant-Idonly after confirming that the final request origin exactly matches an approved origin. - Disable automatic cross-origin redirects or validate every redirect target before forwarding authentication headers.
- Reject plain HTTP endpoints to prevent credentials and content from being transmitted without transport encryption.
- Separate development endpoint overrides from production behavior and require an explicit, clearly named development mode for non-production hosts.
- Use short-lived, narrowly scoped credentials where supported, and rotate any key suspected of having been used with an untrusted endpoint.
- Add automated tests covering malicious schemes, unapproved domains, embedded credentials, unexpected ports, and redirect-based credential leakage.
- Pin the execution endpoint to
